The vendor explicitly identifies these products as affected by this CVE.
- httpd as a component of Red Hat Enterprise Linux 6
- httpd-devel as a component of Red Hat Enterprise Linux 6
- httpd-manual as a component of Red Hat Enterprise Linux 6
- httpd-tools as a component of Red Hat Enterprise Linux 6
- httpd.src as a component of Red Hat Enterprise Linux 6
- mod_ssl as a component of Red Hat Enterprise Linux 6
- httpd as a component of Red Hat Enterprise Linux 7
- httpd-devel as a component of Red Hat Enterprise Linux 7
- httpd-manual as a component of Red Hat Enterprise Linux 7
- httpd-tools as a component of Red Hat Enterprise Linux 7
- httpd.src as a component of Red Hat Enterprise Linux 7
- mod_ldap as a component of Red Hat Enterprise Linux 7
- Summary
- A flaw was found in the mod_auth_digest module of httpd. A remote unauthenticated attacker can bypass digest authentication by measuring timing discrepancies of requests. This issue leads to unauthorized access to resources protected by digest authentication.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
